Alert · reviewed · open
Transaction Risk Skoor 40 (review band) on a $574.43 ach transfer: returns.counterparty_prior_unauthorized.
- Detector
- skoor_review
- Severity
- medium
- Program
- Lantern Lending (simulated)
- Subject
- transfer acht_sim_lant_bfgy2p57ef2
- Transfer
- acht_sim_lant_bfgy2p57ef2 · $574.43 · ach outgoing
- Skoor at alert
- 40 review
- Hard signal
- no
- Policy
- policy-v1
- Opened
- 2026-09-17 19:32Z
- Closed
- —
- Decision clock
- none · due — no clock
- Escalated
- —
Draft narrative
What happened. An outgoing ACH credit transfer of $574.43 from Lantern Lending (simulated) to counterparty cpty_sim_lant_asr3v7ggcjp was flagged by the skoor_review detector at a risk score of 40 (review band) due to a single signal: the counterparty has one prior unauthorized ACH return on record.
What the evidence shows. The transfer (acht_sim_lant_bfgy2p57ef2) settled with no return code, indicating it completed without issue. The only signal driving the score is 'returns.counterparty_prior_unauthorized' (weight 40), based on one prior unauthorized return for this counterparty; no detail on when that return occurred or its context is provided. The subject entity, Fern Studio 317, is VERIFIED, not high risk, not PEP, has no open review reasons, and was screened on 2026-09-05. Program-level KRIs show ach_unauthorized_return_rate at 0 (n=271, ok) and stale_screening_share at 0, meaning the program is not currently showing elevated unauthorized-return activity beyond this one flagged counterparty history.
What was checked. Transfer status and return code, entity verification and risk flags, program KRI panel for unauthorized/administrative return rates and screening staleness, and prior dispositions for this alert or subject. No prior dispositions exist. The one KRI breach on the panel (manual_review_aging_hours) reflects aggregate review backlog, not this specific alert or counterparty.
What is recommended. Close the alert. The flagged transfer has already settled cleanly with no return, the subject entity is verified with no other risk indicators, and the single driving signal is an isolated historical event for the counterparty that has not recurred in program-wide return metrics. No funds are pending or held on this transfer, so no hold or release action applies. If the counterparty's prior unauthorized return recurs on a future transfer, that would warrant escalation to assess a pattern.
- Recommendation
- close
- Confidence
- 0.68
- Model
- claude-sonnet-5
- Drafted
- 2026-09-17 19:32Z
- Rationale
- Transfer status is SETTLED with return code none; the flagged transaction itself shows no unauthorized return.
- Single signal (weight 40) with no detail on the date or amount of the prior unauthorized return, limiting ability to assess recency or severity.
- Subject entity is VERIFIED, not high risk, not PEP, with no open review reasons and recent screening (2026-09-05).
- Program KRI ach_unauthorized_return_rate is 0 across n=271, indicating no broader pattern of unauthorized returns tied to this program.
- No prior dispositions exist for this subject or alert, so there is no history of repeat flags to justify escalation.
- Because the transfer has already settled, hold/release actions do not apply; there is no pending transfer to act on.
Evidence
{
"n": 765,
"band": "review",
"skoor": 40,
"signals": [
{
"code": "returns.counterparty_prior_unauthorized",
"detail": "1 prior unauthorized return(s)",
"weight": 40
}
],
"confidence": 0.925,
"routeReason": "detector not auto-closable"
}
Skoor signals
| Signal | Weight | Hard | Detail |
|---|---|---|---|
| returns.counterparty_prior_unauthorized | +40 | 1 prior unauthorized return(s) |
Decision
Sign in as an operator to decide. Operator sign-in →
Dispositions
No disposition yet.
Actions
Freeze, request to program, and suspend need a second, distinct approver. Clear hold, cancel, and pause execute on the requester's approval. Executed through the bank's own API with the tenant's sandbox key; a dry run when there is none.
No actions requested.